Trojan

What is “Trojan.Win32.Agent.xaljfq”?

Malware Removal

The Trojan.Win32.Agent.xaljfq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xaljfq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Icelandic
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Win32.Agent.xaljfq?


File Info:

name: 622012D8733D3285FDB8.mlw
path: /opt/CAPEv2/storage/binaries/4329f061b826a13a4116bf4643d6e3c2d6ade09e20183c5c4ea856f876cd0919
crc32: 51A25277
md5: 622012d8733d3285fdb84c31bba0bef2
sha1: 723a232a6871c21f08400ee948f2a22301500816
sha256: 4329f061b826a13a4116bf4643d6e3c2d6ade09e20183c5c4ea856f876cd0919
sha512: c512ad3784e0cd8dd2a53d2b42b2b537207d02c24bba7e040cc0544861a87475afb4c5a8641ec0b4702efc7245e8876978eee60ef86f9179118b2080b7cca364
ssdeep: 3072:QPtQVavt7dm+4QoabePHH7b7AC5UdNsNqfhQD6c0UhsZVggjcGkNIVqIe52:Mtxm+4QXOId+g5QD61b7ITsqs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19604AED276E1D471C6A23D704460BBE44E7BBC61EB7045CB367C129E6F7A2C09636722
sha3_384: dbd4f4efb5814f25c101712f4c417f9a9eede4352ec01e0edafe2f87ecab7d1fd0d66ed4242235503495cfb85eec6bbd
ep_bytes: e8a3370000e978feffffcccccccccccc
timestamp: 2021-03-16 16:07:10

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 23.54.77.27
Translation: 0x0127 0x046a

Trojan.Win32.Agent.xaljfq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.4305
MicroWorld-eScanTrojan.GenericKD.47633335
FireEyeGeneric.mg.622012d8733d3285
ALYacTrojan.GenericKD.47633335
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058bbc51 )
AlibabaTrojan:Win32/Azorult.3d722251
K7GWTrojan ( 0058bbc51 )
Cybereasonmalicious.a6871c
BitDefenderThetaGen:NN.ZexaF.34114.lu0@a8tNu@gG
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNQQ
TrendMicro-HouseCallTROJ_GEN.R03FC0DLF21
Paloaltogeneric.ml
ClamAVWin.Dropper.Tepfer-9916200-0
KasperskyTrojan.Win32.Agent.xaljfq
BitDefenderTrojan.GenericKD.47633335
AvastWin32:Trojan-gen
TencentTrojan-Spy.Win32.Stealer.16000121
Ad-AwareTrojan.GenericKD.47633335
EmsisoftTrojan.Crypt (A)
TrendMicroTROJ_GEN.R03FC0DLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Mal/Agent-AWV
IkarusTrojan-Ransom.StopCrypt
JiangminTrojan.Agent.dsxy
eGambitUnsafe.AI_Score_51%
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34EE20A
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Azorult.RMA!MTB
ViRobotTrojan.Win32.Z.Stopcrypt.185856.A
GDataWin32.Trojan.BSE.13HWNF8
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R457879
Acronissuspicious
McAfeeRDN/Smoke Loader
VBA32Malware-Cryptor.2LA.gen
APEXMalicious
RisingTrojan.Generic@ML.94 (RDMK:67HdoKMAoI2+OzleXzNDkw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agent.xaljfq?

Trojan.Win32.Agent.xaljfq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment